The portal of Italy's Revenue Agency. 81 requests, only 2 domains — everything on government infrastructure, with no Google and no social networks. But the policy promises only anonymous aggregate statistics and denies profiling, while the site records the individual visitor's session — clicks, cursor, scrolling — and does so before the banner appears, and without a single cookie.
Timeline of the leak
Declared versus actual
Detected trackers
- Sogei government analytics (Matomo)
- Matomo HeatmapSessionRecording — session recording and heatmaps
- Cookieless tracking (without a single cookie, via an identifier and browser fingerprint)
Indicators of GDPR non-compliance
- Art. 13(1)(e) and Art. 5(1)(a) GDPR — undeclared session recordingThe policy promises only anonymous aggregate statistics and explicitly denies profiling. In the capture, however, a separate session-recording module is active: it logs the behaviour of a specific visitor — clicks, cursor movement, scrolling — under an individual identifier. This is the opposite of «aggregate and anonymous». The module is not mentioned in the document by a single word. The same module was found on the Cybersecurity Agency's site — meaning this is not the chance of a single portal, but a trait of the shared platform of the provider Sogei.
- Art. 6(1)(a) GDPR / Italian regulator's guidance — tracking before consentUnder the Italian regulator's rules (Garante, 2021), monitoring visitor behaviour is not a technical cookie but a separate tracking tool that requires consent. On the site, however, the session recording launches at the 462nd millisecond, while the code of the cookie banner loads only at the 554th — that is, the tracking is already under way before the banner has even appeared, and is treated as requiring no consent.
- Art. 5(1)(a) GDPR — data is transmitted that is «not transmitted»The document states that personal information is not transmitted. Yet the visit measurement carries to the server the visitor's identifier, the screen resolution, the type of network connection and a detailed browser fingerprint. This is at the least a de-identified device profile, not an impersonal counter.
Context
www.agenziaentrate.gov.it is the portal of the Agenzia delle Entrate, Italy’s tax authority. It is built on the Liferay platform. The capture shows only 81 requests to two domains: the portal itself and the government analytics infrastructure of the provider Sogei. Credit is due right away: there is no Google here, no YouTube, no social-network widgets, no transfer of data abroad — everything runs on government infrastructure. By this criterion the portal is noticeably cleaner than many. Separately, a note on the document itself. The live policy page could not be read head-on — the site blocks automated access with bot protection. So I verified the text against the official publication of the policy and against an export from the Wayback Machine (web.archive.org): both versions match word for word, so the wording below is exact. The policy applies to a list of the Agency’s sites and applications and names the company Sogei as responsible for the processing of navigation data. And with such outward cleanliness, the main problem is inside: what the site does with the visitor is not described in the policy.
Was there a consent banner — and when
There is a banner, but by the time it appears the tracking is already working.
- +0.35 s — the government analytics script loads.
- +0.46 s — the visit measurement is sent.
- +0.462 s — the session-recording module launches for a specific identifier.
- +0.554 s — and only now does the code of the cookie banner load. The gap is small in time — less than a hundred milliseconds — but fundamental: both the analytics and the behaviour recording start before the consent mechanism even appears on the page. That is, by the moment when something could be offered to the visitor, their session is already being recorded.
The site records the session — while the policy promises only anonymous statistics
This is the heart of the analysis. The policy describes analytics strictly as the collection of information «in aggregate form» — how many visitors in total and how they move around the site overall — and, in a separate phrase, denies profiling. But in the capture it is not an aggregate counter that works. There a session-recording and heatmap module is active — a tool that logs the behaviour of a specific visitor: where they clicked, how they moved the cursor, how they scrolled the page — and ties this to an individual identifier. By its very nature this is the opposite of «aggregate and anonymous»: an aggregate does not store individual sessions, while session recording does precisely that. In the document there is not a word about this functionality. An important detail is that this is not a one-off glitch: the exact same module on the same government infrastructure was found on the Cybersecurity Agency’s site too. That is, this is a systemic trait of the provider’s platform, not the oversight of a single portal — and most likely it is replicated on other government sites built on the same foundation.
Tracking without a single cookie
The most curious thing is exactly how this is done. Throughout the whole session the site did not set a single cookie. Zero. And here a trap arises: the whole policy is built around the word «cookie» — it promises that cookies are not used for profiling and do not transmit personal data. By the letter this is even true: there really are no cookies. But the tracking is nonetheless under way. Just not through cookies — directly, via the visitor identifier and browser fingerprint, which are passed right in the body of the request at each measurement. It turns out the policy’s promises are formally kept, because they concern only cookies — while the actual tracking simply bypasses the very entity the policy talks about. For an ordinary reader this is the catch: they are told about cookies to reassure them, while the tracking happens past the cookies.
What exactly goes out in the measurement
Not to be unsubstantiated — here is what flies off to the server together with the fact of a visit: the visitor identifier, the screen resolution, the type of network connection and a detailed list of browser and system versions. This is no longer an impersonal unit in a counter, but a recognisable device profile. The policy, meanwhile, separately states that personal information is not transmitted. One can argue how «personal» such a profile is after de-identification — but clearly more is transmitted than is needed for a simple headcount.
By the regulator’s rules this requires consent
And one more layer. The Italian regulator, in its guidance, explicitly distinguishes: technical cookies are one thing, and tools that carry out analysis and monitoring of visitor behaviour are another, and for these explicit user consent is required. Session recording is precisely behavioural monitoring. So classifying it among «technical means requiring no consent» is incorrect already by the regulator’s own position. And on the site it works exactly that way: it launches automatically, before the banner, without a prompt.
Why this is more serious for a tax authority
The capture was taken from the public home page, and the recorded session here is the behaviour of an anonymous guest on the shopfront. But keep the context in mind: this is a tax authority. If the same session-recording module is configured on the pages that already-authenticated users visit with their tax data, the value and sensitivity of such a recording becomes fundamentally different. I will say honestly: from this capture I see only the home page and cannot claim that the recording is also enabled in the personal account. But this is exactly why such a finding on such a body cannot be considered a trifle — it is worth checking separately on the authenticated sections.
What cannot be claimed from the capture
A few honest caveats. The capture covers only the public home page — what happens after logging into the personal account is not visible from here. The lifetimes of stored data cannot be named, but in this case it does not matter: cookies are not set at all. I do not have the scripts’ source code — the conclusions about the recording launching are drawn from the requests themselves in the capture. And, as stated above, the live text of the policy was read not directly (access is blocked by bot protection) but from the matching official publication and export.
Conclusion
From the outside the portal looks exemplary: no third-party trackers, nothing beyond the government infrastructure. But this is exactly why the main finding stands out all the more. The policy promises only anonymous aggregate statistics and denies profiling — while the site records the individual visitor’s session: clicks, cursor, scrolling. It does so before the banner appears, and without a single cookie — bypassing the very entity around which the whole policy is built. By the regulator’s rules such behavioural monitoring requires consent, which is not asked for here. The main takeaway for the reader: the absence of third-party trackers is not the same as the absence of tracking, and in this case the tracking has simply moved to where the policy does not look for it.
4ced4ce3c776d771531aa1add0ea999628f9f148d1ce9526d7e451f397ae43d7Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website agenziaentrate.gov.it. 2. Circumstances I visited the website agenziaentrate.gov.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy promises only anonymous aggregate statistics and explicitly denies profiling. In the capture, however, a separate session-recording module is active: it logs the behaviour of a specific visitor — clicks, cursor movement, scrolling — under an individual identifier. This is the opposite of «aggregate and anonymous». The module is not mentioned in the document by a single word. The same module was found on the Cybersecurity Agency's site — meaning this is not the chance of a single portal, but a trait of the shared platform of the provider Sogei. 2) Under the Italian regulator's rules (Garante, 2021), monitoring visitor behaviour is not a technical cookie but a separate tracking tool that requires consent. On the site, however, the session recording launches at the 462nd millisecond, while the code of the cookie banner loads only at the 554th — that is, the tracking is already under way before the banner has even appeared, and is treated as requiring no consent. 3) The document states that personal information is not transmitted. Yet the visit measurement carries to the server the visitor's identifier, the screen resolution, the type of network connection and a detailed browser fingerprint. This is at the least a de-identified device profile, not an impersonal counter. Full technical documentation is published at: https://gdpru.eu/en/audits/it-agenziaentrate-gov-it/ 3. Provisions violated Art. 13(1)(e) and Art. 5(1)(a) GDPR — undeclared session recording; Art. 6(1)(a) GDPR / Italian regulator's guidance — tracking before consent; Art. 5(1)(a) GDPR — data is transmitted that is «not transmitted» 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]